Free Trial

Safari Books Online is a digital library providing on-demand subscription access to thousands of learning resources.


Share this Page URL
Help

Autopsy and Open Source > Autopsy and Open Source - Pg. 303

ForensicAnalysisofMobileMalware·Chapter9 303 range to monitor information such as network login traffic, infrared transmissions, and any applications being used. PDA Seizure (Paraben) PDA Seizure is a comprehensive tool that assists in seizing the PDA. It allows the data to be acquired, viewed, and reported on. PDA Seizure works within a Windows environment and can extract the random access memory (RAM) and read-only memory (ROM). It has an easy-to-use graphical user interface (GUI), and includes the tools needed to investigate files contained in a PDA. PDA Seizure provides multiplatform support, where the forensic examiner can acquire and examine information on PDAs for both the Pocket PC and Palm operating system (OS) platforms. The PDA Seizure tool has a significant amount of features, including forensic imaging tools, searches on data within acquired files, hashing for integrity protection of acquired files, and a book-marking capability to assist the examiner in the organization of information. The product provides combined PDA and Cell Seizure into Device Seizure and has been considered the "standard" for PDA and mobile device forensics for a long time. It provides both logical and filesystem acquisition.